SQL Injection Vulnerability in SourceCodester Medicine Tracker System
CVE-2024-6419

9.8CRITICAL

Key Information:

Vendor
CVE Published:
1 July 2024

Summary

A significant SQL injection vulnerability exists within SourceCodester's Medicine Tracker System version 1.0, specifically in the save_medicine function located in the Master.php file. This vulnerability allows attackers to manipulate the 'id' parameter, potentially leading to unauthorized access to the underlying database. The exploit can be executed remotely, posing a serious threat to data integrity and security. With public disclosure of this vulnerability, urgent measures are recommended to mitigate the risks associated with this exploit. Organizations using this system should prioritize patching and apply appropriate security protocols to protect sensitive data.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.